Privacy Policy
Last updated: 31 July 2026 · Controller: SLP Command · privacy@slpcommand.com
This Privacy Policy explains what personal data SLP Command processes, why, on what legal basis, with whom it is shared, how long it is retained, and what rights you have under the General Data Protection Regulation (EU) 2016/679 ("GDPR") and Spanish Organic Law 3/2018 (LOPDGDD).
1. Data controller
SLP Command is the data controller responsible for the personal data described in this Policy. Contact: privacy@slpcommand.com. Full controller identification data is available in the Legal Notice.
2. Categories of personal data we process
- Account data: your email address and a password hash (passwords are managed by our authentication provider — we never store them in plain text).
- Learning content: written responses (Writing), audio recordings (Speaking — optional, consent-based), and AI-generated transcripts of that audio.
- Performance data: scores, estimated SLP levels, exercise history, and the derived Adaptive Coach / Intelligence Dashboard insights.
- Support data: if you submit a report via "Report a Problem", we process the category and free-text description you provide, together with your app version, iOS version, and the screen name.
- Subscription and purchase data: if you subscribe to SLP Command Professional, we process a technical subscriber identifier linked to your account, the App Store product identifier, App Store transaction identifiers, subscription status, and purchase/renewal/expiration dates. This information reaches us through RevenueCat, our subscription-management technology provider — see §4. We do not receive or store your payment card number or other full payment credentials; your payment itself is handled directly by Apple as an independent party, not by us — see §4a.
- Product usage data: pseudonymous, event-level analytics describing which features and screens you use (e.g. module opened, quiz completed, exam started), your app version, and a pseudonymous user identifier. This data never includes your written answers, audio, transcripts, or any content you submit.
- Technical & security data: a pseudonymous user identifier, IP address (processed transiently for rate-limiting and abuse prevention, and stored in hashed, non-reversible form in our security audit trail — see §6.5), device/app version, and crash or error diagnostics stripped of personal content.
- Security audit trail: a limited, append-only log of security-relevant account events (e.g. login, account creation, account deletion) associated with a pseudonymous user identifier and a hashed IP address, retained according to the schedule in §6.5.
We do not collect your name, postal address, phone number, government identifiers, location data, advertising identifiers, military rank, unit, service branch, or employer. We do not track you across other apps or websites.
3. Legal bases for processing (Article 6 GDPR)
- Performance of a contract (Art. 6.1.b): account provisioning, progress synchronisation, delivery of exercises, Writing feedback, score history, and the Adaptive Coach / Intelligence Dashboard.
- Explicit consent (Art. 6.1.a): processing your Speaking audio for transcription and AI evaluation. This consent is requested separately, in context, before your first use of the Speaking feature, and is entirely optional — you can use every other feature of the Service without ever granting it. You may withdraw it at any time.
- Legitimate interest (Art. 6.1.f): maintaining the security, stability, integrity and abuse-resistance of the Service, and understanding aggregate, pseudonymous product usage to improve it.
4. Sub-processors
To deliver the Service, we share personal data with the following processors, each bound by a data processing agreement requiring it to act only on our instructions. See the full Subprocessors and Third Parties page for details.
- Supabase — database, authentication, audio file storage.
- OpenAI — Whisper (speech-to-text transcription) and GPT models (evaluation of Speaking and Writing responses across fluency, grammar, vocabulary, coherence and task achievement).
- ElevenLabs — text-to-speech audio generation for listening exercises and pronunciation models. No personal data is sent — only exercise text.
- Render — backend API hosting.
- Sentry — crash and error diagnostics. Request bodies and authorization headers are stripped before transmission; no personal content or audio is sent to Sentry.
- PostHog — pseudonymous product usage analytics (feature/screen usage, app version). Never your written answers, audio, transcripts, or account email.
- RevenueCat — subscription-management technology provider; validates your App Store purchase and tracks subscription status so the app can grant Professional-plan access.
We do not sell your personal data to any third party. We do not permit AI providers to use your Content to train their general-purpose models, except where you have given separate, explicit consent.
4a. Apple — an independent party, not our processor
Apple Inc. operates the App Store, through which the app is distributed and through which any subscription purchase is made. For that purchase, Apple is not a processor acting on our instructions: Apple determines the purposes and means of processing your payment, your Apple ID, and your purchase history itself, under Apple's own Privacy Policy. We only receive, via RevenueCat, the limited technical information described in §2 above — never your full payment details.
5. International transfers
Some of the providers listed above process data outside the European Economic Area, principally in the United States. Where this occurs, transfers rely on appropriate safeguards under Article 46 GDPR, including the European Commission's Standard Contractual Clauses and, where applicable, provider participation in the EU-US Data Privacy Framework.
6. Retention
See the full Data Retention Policy for the itemised schedule. Summary:
- Account, progress, scores, transcripts, written responses: retained for the life of your account, then permanently deleted within 30 days of account deletion.
- Speaking audio recordings: retained only while you keep them. You can delete individual recordings from the App at any time. All audio is permanently removed when you delete your account.
- Support requests: retained for 12 months from submission, or until account deletion, whichever comes first.
- Diagnostic / crash logs: retained short-term only (typically 30–90 days).
- Subscription and billing records: while your account is active, we keep the subscription data described in §2. If you delete your account, the identifiers linking those records to you are removed and the remaining technical/financial fields are kept, dissociated from your account, only for as long as necessary for the purposes described in §3 of the Data Retention Policy.
- Security audit trail (§6.5): by exception, security-relevant events (login, account creation, account deletion, administrative actions) are retained for 12 months from the date of the event, irrespective of account deletion, on the basis of our legitimate interest (Art. 6.1.f) in investigating fraud, abuse and security incidents. This entry never contains your email, written content, audio or transcripts — only event type, a pseudonymous identifier, a hashed IP address, and a timestamp. Once your account is deleted, this identifier no longer resolves to any identifiable individual within our systems. Every entry is automatically and permanently purged 12 months after creation.
7. Your rights (EEA / UK — GDPR / LOPDGDD)
You have the right to access, rectify, erase, restrict, object to, and port your data. To exercise any of these rights, contact privacy@slpcommand.com. We will respond within one month, extendable by two further months for complex requests. You may also lodge a complaint with your supervisory authority — in Spain, the AEPD.
In-app account deletion is available from Settings → Delete Account. See Delete Account for full details.
8. Automated decision-making
The Intelligence Dashboard and Adaptive Coach are computed exclusively from your own historical results within the Service. They do not produce any decision with legal or similarly significant effect on you within the meaning of Article 22 GDPR: they are non-binding, educational recommendations. See the Responsible AI Policy.
9. Audio data and biometrics
Audio recordings are processed solely for speech-to-text transcription and language evaluation. We do not use audio to identify you biometrically. Audio is classified as personal data under GDPR but not as a biometric identifier (Art. 9) because it is not processed for the purpose of unique identification.
10. Children
The Service is not directed at individuals under 16 years of age. If we become aware that we have collected personal data from a person under 16 without a valid legal basis, we will delete that data. Contact privacy@slpcommand.com if you believe this has occurred.
11. Security
See the Security Policy for the full statement of technical and organisational measures.
12. Changes to this policy
We may update this Policy from time to time. Material changes affecting the sub-processors in §4 or the retention schedule in §6 will be notified via the Service or by email at least 15 days before taking effect.
13. Contact
privacy@slpcommand.com